Forum Discussion
Sharing semantic models through intermediary
- 8 months ago
Hi DouweMeer ,
Thanks for the follow up.
Assigning an AD group with read access may not prevent a user with reshare and build from granting additional permissions. If they choose to share and allow build, that direct permission might still apply alongside the group’s read access, since permissions are handled in an additive way.If you want to ensure only read access is propagated, the reshare permission would need to be restricted.
Please reach out for further assistance.
Thank you.
Hi DouweMeer ,
Thanks for raising this.
The explanations provided from ibarrau and lbendlin cover the scenario accurately. Reshare inherently allows the recipient to pass on the same permissions, so restricting them to share only with read access is not supported. You would need to manage permissions directly or ensure the intermediary does not grant additional rights when sharing.
If you need further clarification on permission behaviours, feel free to reach out.
Thank you.